What the number is saying
CRQ stands for cyber risk quantification. The practice expresses security risk as money and probability, in place of a color scale or a count of open vulnerabilities.
A typical output reads like this: a 12% chance of a loss above $20 million over the next twelve months, in that scenario, under those assumptions. It is a stated bet, with the arithmetic in the open for anyone who wants to argue with it.
The problem with the heat map
High, medium, and low do not add up. Two items both marked high can sit two orders of magnitude apart in loss, and the matrix hides the gap. When the CFO asks what doing nothing costs, an answer in red goes into no spreadsheet.
The qualitative scale has another uncomfortable property: it can never be publicly wrong. A dollar figure, with a range and a written assumption, can be refuted by anyone who disagrees. That is the method's advantage, though almost nobody sells it that way.
The two metrics the analysis produces
Annualized loss expectancy, ALE, is the projected average loss per year for that scenario. It works for comparing scenarios against each other and for sizing a budget.
The upper percentile of the distribution, VaR at P90 or P99, is the other half. That is where the rare, expensive event lives, and it is usually the reason the meeting exists at all. Present the average alone and you have hidden the tail.
Both numbers come out of a distribution, and the distribution comes from a decomposition method. The common one is FAIR, which splits risk into loss event frequency and loss magnitude and simulates over ranges rather than fixed values.
Where the magnitude comes from
No company holds enough internal history to calibrate, on its own, the cost of an event it has almost never lived through. Public reference is what holds the estimate up.
IBM's Cost of a Data Breach 2025 puts the average breach in the United States at $10.22 million, against a global average of $4.44 million. In the global sector table, healthcare sits at $7.42 million and financial services at $5.56 million. These are anchors, and each one needs adjusting for company size and for the kind of data the business holds.
The regulatory share is harder to bound in the United States than in Europe, because there is no single federal ceiling and the exposure varies by state and by sector. For a company holding EU personal data, GDPR gives a bound worth modeling separately: up to 4% of global annual turnover or €20 million, whichever is higher. The risk calculator produces a first estimate on the same public base.
The mistake that loses the room
False precision. A model fed by interval estimates returning $18,473,219 loses the room at the first director who asks where the 219 came from.
A range is the honest answer and the more useful one. "Between $8 and $31 million, at 90% confidence" says where the uncertainty sits and points at the variable worth researching next cycle. What to do with that number inside a board meeting is a separate piece.
What breaks the model first
A wrong inventory. Event frequency depends on how many reachable assets exist and what kind they are. If the company cannot say which of its services answer on the internet today, half the calculation is wrong at the source, and no refinement of magnitude repairs it.
That is why mature quantification stays tied to a continuous exposure management program that keeps the inventory current on its own. An annual analysis describes a state that no longer exists on the day it reaches the board. That link is what CSURFACE's risk quantification runs on: externally observed exposure feeding the model, with the value re-scored when the surface changes.
CRQ, CVSS, and security ratings
Three numbers that show up in the same meeting and measure different things.
CVSS measures the technical severity of a flaw under conditions ideal for the attacker. It knows nothing about the value of the asset or the odds that anyone will try.
A security rating summarizes externally observable posture as a comparative score. It works for vendor triage and does not hold up a capital decision.
CRQ is the only one of the three denominated in money, and the only one that answers how much gets lost.
Where CRQ does not help
It does not decide which fix goes in on Tuesday morning. The granularity is wrong for that, and pushing the model down to that level produces modeling work nobody will read.
It also does not replace detection and response, because it estimates probability without lowering it. And a badly calibrated model ends up worse than the heat map it replaced: it carries the authority of a number with nothing behind it.